Oringnet's vulnerability footprint centers on its IAP-420 industrial access point and associated firmware, a narrowly scoped but strategically positioned product in operational-technology and network-edge deployments. Vulnerabilities affecting this vendor skew toward serious outcomes and recur through input-handling and command-execution weakness classes—including cross-site scripting, command injection, OS command injection, and improper exception handling—that reflect the product's web interface and system-level functionality. Defenders should prioritize patches for this firmware line given its critical-severity tendency; live exploitation and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oringnet over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5411HIGH Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e | May 28, 2024 | 8.8 | 36 | NO | NO |
CVE-2024-55547CRITICAL SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e. | Dec 10, 2024 | 9.8 | 34 | NO | NO |
CVE-2022-3203CRITICAL On ORing net IAP-420(+) with FW version 2.0m a telnet server is enabled by default and cannot permanently be disabled. You can connect to the device via LAN or WiFi with hardcoded | Oct 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-55544HIGH Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below. | Dec 10, 2024 | 8.8 | 30 | NO | NO |
CVE-2024-5410MEDIUM Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | May 28, 2024 | 5.4 | 26 | NO | NO |
CVE-2024-55548HIGH Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue affects IAP-420: through 2.01e. | Dec 10, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-55545MEDIUM Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | Dec 10, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-55546MEDIUM Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below. | Dec 10, 2024 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oringnet.
Media articles that mention a CVE ID that affects a product developed by Oringnet — matched by CVE ID, not by vendor name.